Technical Lead – Microsoft Entra / Global Secure
We at WeQuel are now looking for an experienced Technical Lead – Microsoft Entra / Global Secure Access in Södertälje, where you will become a key part of the IAM team, with a focus on the design, implementation, operation and continued development of Microsoft Entra Global Secure Access, initially Entra Private Access. The assignment combines technical leadership, platform engineering, application onboarding, operational responsibility and complex troubleshooting within a large enterprise environment. You will take a leading technical role in developing a scalable and resilient Global Secure Access platform, and you will also contribute to the maintenance, support and continued development of other functionality within Microsoft Entra. As a consultant with us, you will have the opportunity to work with one of our clients, who are leading companies within industry, technology and IT security. You will help strengthen secure access, implement Zero Trust solutions and build resilient, sustainable platforms. Your responsibilities: Ownership of the technical design and continued development of the Microsoft Entra Global Secure Access platform Design and maintenance of scalable Entra Private Access architecture, covering Private Network Connectors, connector groups, high availability, failover, capacity planning, application segmentation and regional/data-centre resilience Configuration and governance of application access through Microsoft Entra ID, security groups, application assignments, Conditional Access, device compliance, MFA and Zero Trust principles Leading the onboarding and migration of internal applications from VPN and similar solutions to Private Access Analysis of application connectivity requirements, including DNS, TCP/IP, ports, routing, authentication and TLS Establishing technical standards, configuration baselines, deployment patterns and rollback procedures Monitoring of platform health, connector availability, capacity, traffic flows, authentication and policy synchronisation Leading complex incident resolution, root-cause analysis and problem management Developing and maintaining operational documentation, runbooks, troubleshooting guides and support procedures Support for security assessments, risk management, audit activities and service readiness reviews Coordination of technical activities with Microsoft Support and internal platform teams Contribution to future service expansion, including Entra Internet Access where relevant Mentoring of other engineers and promoting knowledge sharing across the organisation Implementing changes through appropriate change-management and release processes You will work closely with the Product Owner and the wider IAM team, as well as the Network, Endpoint/Client, Security, SOC, Service Desk, infrastructure and application teams. In this role you drive the technical direction independently while collaborating across many interfaces within the organisation. Requirements: Microsoft Entra & Identity Strong hands-on experience with Microsoft Entra ID in a large enterprise environment Practical experience with identity-based access control, security groups, application assignments and entitlement models Strong understanding of Conditional Access, including user, device, location, risk and session-based controls Experience implementing or operating MFA and Zero Trust access controls Good understanding of device identity and compliance, preferably with Microsoft Intune and Microsoft Defender Global Secure Access & Private Access Hands-on experience with Microsoft Entra Global Secure Access, Entra Private Access or a similar ZTNA solution Practical understanding of Private Network Connectors, connector groups, connector registration, certificates and outbound connectivity Experience designing for high availability, failover, resilience and capacity management Troubleshooting of traffic forwarding, policy synchronisation and application connectivity Networking & Application Connectivity Strong knowledge of DNS, TCP/IP, routing, firewalls, ports, TLS and HTTP/HTTPS Experience troubleshooting connectivity to internal applications, servers, databases or infrastructure services Understanding of network segmentation and access control for different application and user groups Analysis of technical requirements for file services, RDP, engineering tools, databases and enterprise platforms Operations & Service Management Experience operating business-critical services in production Strong skills in monitoring, logging, incident management and root-cause analysis Experience with change management, release management, technical documentation and operational handover Ability to define support models, runbooks, escalation paths and service-management processes Experience working with Security Operations/SOC teams during investigations and incidents Technical Leadership & Collaboration Proven experience as a Technical Lead, Platform Lead or Senior Engineer Sound technical decision-making and clear communication to technical and non-technical stakeholders Experience coordinating across Identity, Network, Endpoint, Security, Infrastructure and application teams Strong ownership mentality and ability to work independently in a developing product area Ability to mentor engineers and establish consistent technical ways of working Language Fluent English required Meriting Privileged access management, PIM, JIT access and access governance ServiceNow, Jira or similar ITSM and workflow platforms Knowledge of ISO 27001, NIST Zero Trust, DORA, GDPR or similar security and compliance frameworks Risk assessments, BIA, TVA, IRAM or comparable information-security processes Support of macOS and Windows access scenarios Personal qualities Structured, analytical and pragmatic, comfortable with both strategic architecture and detailed troubleshooting Proactive in identifying risks, dependencies and operational weaknesses Comfortable taking ownership
Findigo hittar jobben och fyller i ansökan. Du klickar Skicka.
Visa jobbet och ansökUrsprunglig annons: career.wequel.se